Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
234 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.4) | 0.69% | — | RenovateAIHelmAI | 19/8/2026 | 1/10/2026 | Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows attackers with commit access to execute arbitrary commands. Attackers can manipulate registryAliases keys with unquoted shell metacharacters to inject commands executed… | |
| Analizada | Alta (7) | 0.13% | — | IBM Powervm Novalink | 17/7/2026 | 11/8/2026 | IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintended or unauthorized operations under non-default conditions. | |
| Analizada | Alta (7.5) | 0.55% | — | IBM Powervm Novalink | 17/7/2026 | 11/8/2026 | IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the server to consume memory resources. | |
| Aplazada | Crítica (9.8) | 0.56% | — | Novalnet Payment GatewayAI | 2/7/2026 | 2/7/2026 | Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions. | |
| Analizada | Alta (8.5) | 0.46% | — | Openstack Nova | 16/6/2026 | 26/6/2026 | In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation. | |
| Aplazada | Media (6.5) | 0.34% | — | Nova-toggleAI | 8/5/2026 | 17/6/2026 | nova-toggle-5 enables fliping booleans in the index. Prior to version 1.3.0, the toggle endpoint (POST/nova-vendor/nova-toggle/toggle/{resource}/{resourceId}) was protected only by web + auth:<guard> middleware. Any user authenticated on the configured guard could call the endpoint and flip boolean attributes on any… | |
| Pendiente de análisis | Media (5.3) | 0.52% | — | Cpanel Nova PluginAI | 8/5/2026 | 17/6/2026 | A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on arbitrary system files or directories. That can cause DoS or local privilege escalation when an authenticated cPanel user places a symlink at a user-controlled legacy Nova path under their home… | |
| Aplazada | Media (5.3) | 0.46% | — | NovagalleryAI | 8/5/2026 | 17/6/2026 | novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGallery. This allows unauthenticated users to read image files outside the intended gallery root directory. This issue has been patched in version 2.1.1. | |
| Aplazada | Alta (8.2) | 0.38% | — | Openstack NovaAIQemu-imgAI | 18/2/2026 | 11/9/2026 | An issue was discovered in OpenStack Nova before 30.2.2, 31 before 31.2.1, and 32 before 32.1.1. By writing a malicious QCOW header to a root or ephemeral disk and then triggering a resize, a user may convince Nova's Flat image backend to call qemu-img without a format restriction, resulting in an unsafe image resize… | |
| Aplazada | Media (4.6) | 0.21% | — | GE Vernova EnervistaAI | 10/2/2026 | 17/6/2026 | Vulnerability in GE Vernova Enervista UR Setup on Windows.This issue affects Enervista: 8.6 and previous versions. | |
| Aplazada | Baja (2.9) | 0.24% | — | GE Vernova Enervista UR SetupAI | 10/2/2026 | 17/6/2026 | A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 and prior versions. | |
| Aplazada | Alta (8.2) | 0.33% | — | Codriapp Innovation AND Software Technologies INC HeygarsonAI | 30/1/2026 | 7/8/2026 | Generation of Error Message Containing Sensitive Information vulnerability in Codriapp Innovation and Software Technologies Inc. HeyGarson allows Fuzzing for application mapping. This issue affects HeyGarson: through 30012026. NOTE: The vendor was contacted and it was learned that the product is not supported. | |
| Analizada | Media (6.9) | 0.16% | — | Nova-a Planmanager | 29/1/2026 | 17/6/2026 | Stored Cross-Site Scripting (XSS) in RLE NOVA's PlanManager. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by injecting malicious payload through the ‘comment’ and ‘brand’ parameters in ‘/index.php’. The payload is stored by the application and subsequently displayed without… | |
| Aplazada | Alta (8.7) | 0.37% | — | Laravel NovaAI | 27/1/2026 | 17/6/2026 | Laravel Nova 3.7.0 contains a denial of service vulnerability that allows authenticated users to crash the application by manipulating the 'range' parameter. Attackers can send simultaneous requests with an extremely high range value to overwhelm and crash the server. | |
| Aplazada | Media (6.5) | 0.19% | — | Pixelgrade Nova BlocksAI | 23/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pixelgrade Nova Blocks nova-blocks allows DOM-Based XSS.This issue affects Nova Blocks: from n/a through <= 2.1.9. | |
| Aplazada | Media (6.5) | 0.21% | — | Theplus Innovation THE Plus Addons FOR Elementor PROAI | 7/1/2026 | 30/9/2026 | Missing Authorization vulnerability in POSIMYTH Innovation The Plus Addons for Elementor Pro theplus_elementor_addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Plus Addons for Elementor Pro: from n/a through < 6.3.7. | |
| Aplazada | Alta (7.1) | 0.14% | — | Tenda I24AITenda 4g03 PROAITenda 4g05AITenda 4g08AI+3 | 31/12/2025 | 17/6/2026 | A vulnerability has been found in Tenda i24, 4G03 Pro, 4G05, 4G08, G0-8G-PoE, Nova MW5G and TEG5328F up to 65.10.15.6. Affected is an unknown function of the component Shadow File. Such manipulation with the input Fireitup leads to hard-coded credentials. An attack has to be approached locally. The exploit has been… | |
| Aplazada | Alta (7.1) | 0.43% | — | Novarad Novapacs Diagnostics ViewerAI | 24/12/2025 | 17/6/2026 | NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack. | |
| Aplazada | Media (5.3) | 0.25% | — | T-innova DeportsiteAI | 13/11/2025 | 17/6/2026 | Insecure Direct Object Reference (IDOR) vulnerability in DeporSite of T-INNOVA. This vulnerability allows an attacker to access or modify unauthorized resources by manipulating requests using the 'idUsuario' parameter in ‘/ajax/TInnova_v2/Formulario_Consentimiento/llamadaAjax/obtenerDatosConsentimientos’, which could… | |
| Aplazada | Media (5.3) | 0.35% | — | GE Vernova SmallworldAI | 7/11/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova Smallworld on Windows, Linux allows File Manipulation.This issue affects Smallworld: 5.3.5. and previous versions. | |
| Aplazada | Crítica (9.3) | 0.50% | — | GE Vernova SmallworldAI | 7/11/2025 | 17/6/2026 | Improper Authentication vulnerability in GE Vernova Smallworld on Windows, Linux allows Authentication Abuse.This issue affects Smallworld: 5.3.3 and prior versions for Linux, and 5.3.4. and prior versions for Windows. | |
| Aplazada | Alta (7.5) | 0.30% | — | Karely LLC KanovaAI | 30/10/2025 | 17/6/2026 | Kanova Android App version 1.0.27 (package name com.karelane), developed by Karely L.L.C., contains improper access control vulnerabilities. Attackers may gain unauthorized access to user details and obtain group information, including entry codes, by manipulating API request parameters. Successful exploitation could… | |
| Aplazada | Media (6.5) | 0.20% | — | Tempranova WP Mapbox GL JSAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tempranova WP Mapbox GL JS Maps wp-mapbox-gl-js allows Stored XSS.This issue affects WP Mapbox GL JS Maps: from n/a through <= 3.0.1. | |
| Aplazada | Crítica (9.3) | 0.55% | — | Novakon P SeriesAI | 23/9/2025 | 17/6/2026 | — | |
| Aplazada | Crítica (9.4) | 0.22% | — | Novakon P SeriesAI | 23/9/2025 | 17/6/2026 | — |